Rolling Out Two-Factor Authentication to the Whole Team
Turning on two-factor is easy; getting everyone enrolled without lockouts and complaints is the real work. A four-week rollout plan for a small team.
Two-factor authentication stops most account takeovers, because a stolen password alone is no longer enough. Nobody seriously disputes that. What goes wrong is the rollout: a policy switched on overnight, half the team locked out on Monday, the owner quietly exempting themselves. Here is a plan that avoids those mistakes.
Week 0: decide the rules before you announce anything
- Which systems. Start with the ones that hold client data and the ones that can reset everything else: email, the main records system, file storage, the password manager, banking.
- Which methods. An authenticator app as the baseline; security keys or passkeys for anyone with admin rights or access to money. Text-message codes only as a last resort.
- What happens when someone loses their phone. Backup codes, a second registered method, and a named person who can verify identity and reset. Write this down before you need it.
- No exemptions. Especially not for the most senior people, whose accounts are the most valuable to attack.
Week 1: pilot
Enrol two or three people, including one who is not comfortable with technology. Watch where they get stuck. Common snags: the authenticator app on an old phone, the QR code scanned into the wrong app, the clock on the phone slightly wrong, backup codes saved into the same phone that holds the app.
Turn what you learn into a one-page guide with screenshots. Short, specific, for your systems.
Week 2: announce and book slots
Tell the team why in two sentences, not a lecture: accounts are being taken over with stolen passwords, and this stops it. Then offer fifteen-minute enrolment slots. People enrol faster with someone beside them, and you catch problems before they turn into lockouts.
Week 3: enrol everyone
At each enrolment, make sure the person:
- Registers the primary method and signs in with it once.
- Saves backup codes somewhere that is not the same phone, such as the password manager or a printed copy kept securely.
- Adds a second method where the system allows it, such as a security key.
- Knows who to call if they are locked out.
Week 4: enforce
Only now switch the setting that requires two-factor for everyone. Check the list of accounts that are still not enrolled, including shared and service accounts, which are often forgotten. A shared login should become individual accounts first; two-factor on a shared account either locks people out or ends up with the codes pinned to a wall.
After the rollout
- Joiners enrol on day one, as part of the account set-up, not "when they get round to it".
- Leavers have their methods removed the day they go.
- Lost devices follow the written recovery process, including an identity check. Attackers phone help desks pretending to be staff who lost their phone.
- Review the enrolment list every quarter.
Expect the objections
"It takes too long" — a few seconds per sign-in, and many systems remember a trusted device. "I do not want work apps on my phone" — offer a security key instead. "I am too senior to be targeted" — the opposite is true. Most successful attacks against small firms start with a convincing email, as described in how small firms get caught by phishing, and two-factor is the layer that holds when someone clicks. Pair it with the basics in password hygiene for small offices.